Both kill standing credentials. One brokers sessions to hosts; the other builds the network the hosts live on.
| OpenVLAN | Boundary | |
|---|---|---|
| Model | Network layer — any connection, any protocol | Session broker for SSH/DB/HTTP |
| Self-serve app access | Users connect directly to allowed services | Through broker each time |
| Non-brokered protocols (RDP, custom TCP) | First-class | Limited / via workers |
| Infrastructure to run | None (SaaS control plane) | Controllers + workers (or HCP-managed) |
| Session recording | Built in (SSH) | Session/credential monitoring |
| Whole-network use (DNS, Taildrop, k8s) | Native | Out of scope |
| IaC ergonomics | Terraform provider + ACLs as code | Terraform-native |
You live in HashiCorp land, need strict broker-style access to specific hosts, and already operate Vault for credentials.
You want one network for everything — access control included — without running brokers, workers, or per-protocol gateways.